Method and system for evaluating security for an interactive service operation by a mobile device
Summary by NHIP
Mobile Security Evaluation Method
A security component on a mobile device evaluates an interactive service by verifying a target website's domain registration against an entity. The system generates a security evaluation using trust factors for the device, service, and network, then allows operation only if measures stay below a threshold.
Claim Score by NHIP
Abstract
A method for evaluating security during an interactive service operation by a mobile communications device includes launching, by a mobile communications device, an interactive service configured to access a server over a network during an interactive service operation, and generating a security evaluation based on a plurality of trust factors related to a current state of the mobile communications device, to a security feature of the application, and/or to a security feature of the network. When the security evaluation is generated, an action is performed based on the security evaluation.

Term
6.9 yearsleft in the term
Expires 9 August 2033, including 107 days of term adjustment.
- Priority and filed
- Granted
- Today
- Expires
26 claims: 3 independent, 23 dependent
- 1A method for evaluating security during an interactive service operation by a mobile communications device, the method comprising:identifying, by a security component on a mobile communications device, a launch of an interactive service configured to communicate with a server over a network during an interactive service operation, wherein the interactive service is associated with an entity and is configured to transmit data to and receive data from a target website purportedly associated with the entity;verifying that the target website is an authentic website associated with the entity, wherein the verifying includes identifying a domain of the target website based on a uniform resource locator (URL) of the target website and includes determining that the domain of the target website is registered by the entity;in response to the launch of the interactive service, generating, by the security component, a security evaluation of the interactive service based on a plurality of trust factors including: a trust factor related to a current state of the mobile communications device, a trust factor related to a security feature of the interactive service, and a trust factor related to a security feature of the network;and allowing, by the security component, the performance, by the mobile communications device, of the interactive service operation when a security measure from the security evaluation does not go beyond a threshold security measure.
- 21A method for evaluating security during an interactive service operation by a mobile communications device, the method comprising:identifying, by a mobile communications device, a launch of an interactive service configured to communicate with a server over a network during an interactive service operation, wherein the interactive service is associated with an entity and is configured to transmit data to and receive data from a target website purportedly associated with the entity;verifying that the target website is an authentic website associated with the entity, wherein the verifying includes identifying a domain of the target website based on a uniform resource locator (URL) of the target website and includes determining that the domain of the target website is registered by the entity;in response to the launch of the interactive service, determining, by the mobile communications device, a security score for the interactive service based on a plurality of trust factors including: a trust factor related to a current state of the mobile communications device, a trust factor related to a security feature of the interactive service, and a trust factor related to a security feature of the network;generating a security evaluation for the interactive service based on the security score;and displaying, by the mobile communications device, the security evaluation for the interactive service and/or a contextual information overlay associated with the interactive service comprising a checklist that includes information regarding a current security status of the mobile communications device, a security status of the interactive service, and a security status of the network, wherein the security evaluation and/or the contextual information overlay is displayed while the user is using the interactive service.
- 22Broadest claimClaim Score 38, average(NHIP)A method for evaluating security during an interactive service operation by a mobile communications device, the method comprising:receiving, by a server having a hardware processor and non-transient computer readable media, an indication from a mobile communications device that an interactive service on the mobile communications device is launched, wherein the interactive service is configured to communicate with another server over a network during an interactive service operation, and wherein the interactive service is associated with an entity and is configured to transmit data to and receive data from a target website purportedly associated with the entity;verifying that the target website is an authentic website associated with the entity, wherein the verifying includes identifying a domain of the target website based on a uniform resource locator (URL) of the target website and includes determining that the domain of the target website is registered by the entity;and in response to the indication of the launch of the interactive service, generating, by the server, a security evaluation of the interactive service based on a plurality of trust factors including: a trust factor related to a current state of the mobile communications device, a trust factor related to a security feature of the interactive service, and a trust factor related to a security feature of the network.
Independent claims3
61 paragraphs in 6 sections, as filed
COPYRIGHT NOTICE
0001A portion of the disclosure of this patent document contains material which is subject to copyright protection. The copyright owner has no objection to the facsimile reproduction by anyone of the patent document or the patent disclosure, as it appears in the Patent and Trademark Office patent file or records, but otherwise reserves all copyright rights whatsoever.
RELATED APPLICATION DATA
0002The present application is a continuation in part application of prior pending application Ser. No. 29/453,039 entitled Graphical User Interface for Notification Icon with Contextual Information Overlay, filed on Apr. 24, 2013; Ser. No. 29/453,040 entitled Graphical User Interface for Notification Icon with Contextual Information Overlay and Selection Bar, filed on Apr. 24, 2013; Ser. No. 29/453,047 Graphical User Interface for Notification Icon with Contextual Information Overlay and Security Icons, filed on Apr. 24, 2013; and, Ser. No. 29/453,048 entitled Graphical User Interface for Notification Icon with Contextual Information Overlay and Privacy Icons, filed on Apr. 24, 2013.
FIELD OF THE INVENTION
0003One or more embodiments relate generally to handheld electronic devices, and more specifically to systems and methods for evaluating security for performing an interactive service operation by a mobile communications device.
BACKGROUND
0004The subject matter discussed in the background section should not be assumed to be prior art merely as a result of its mention in the background section. Similarly, a problem mentioned in the background section or associated with the subject matter of the background section should not be assumed to have been previously recognized in the prior art. The subject matter in the background section merely represents different approaches, which in and of themselves may also be inventions.
0005Mobile electronic communications devices have evolved beyond simple telephones and are now highly complex multifunctional devices with capabilities rivaling, and in some cases surpassing, those of desktop or laptop computers. In addition to voice communications, many mobile communication devices are capable of capturing images, text messaging, e-mail communications, internet access, social networking, and running full-featured application software. A full range of mobile applications are available from online application stores that can be downloaded onto mobile communications devices. These applications can be games and/or services, such as data storage services, mapping services, and/or news services. Additionally, mobile communication devices can run web browsers which can access websites to perform interactive services. In addition, mobile communications devices can support applications that provide interactive services that involve sensitive information or which can perform various electronic transactions. For example, such interactive services can include financial services, such as online banking, stock trading, payments, and other online financial activities. Using these interactive services, a user can purchase merchandise online or at a store, transfer funds between bank accounts, and/or pay monthly bills anywhere any time via the user's mobile communications device. In addition, interactive services may include medical or health information services provided by, for example, a hospital's or doctor's server for scheduling medical appointments or viewing results of medical or diagnostic procedures.
0006While these interactive services offer tremendous conveniences, some users are reluctant to use them for fear of having their sensitive financial, medical, or other information stolen and used without their knowledge and/or authorization. Current anti-virus security applications running on mobile communications devices can detect suspicious applications on the device and can disable or remove such malware. These security applications, however, do not provide a comprehensive security assessment of the device's interactive services environment, of an application while the application is running and/or being used by the user, and/or of a website running in a web browser that provides an interactive service. Hence, the user's fear of revealing sensitive information in a perceived insecure environment is not addressed and therefore, even when the interactive services environment, the application and/or the websites are secure, the user will not utilize the application's financial or other capabilities.
BRIEF DESCRIPTION OF THE DRAWINGS
0007In the following drawings like reference numbers are used to refer to like elements. Although the following figures depict various examples, the one or more implementations are not limited to the examples depicted in the figures.
0008<figref idref="DRAWINGS">FIG. 1</figref> is a block diagram illustrating a mobile communications device according to an embodiment;
0009<figref idref="DRAWINGS">FIG. 2A</figref> is a block diagram illustrating a mobile communications device according to another embodiment;
0010<figref idref="DRAWINGS">FIG. 2B</figref> is a block diagram illustrating an Application Security Assessor module according to an embodiment;
0011<figref idref="DRAWINGS">FIG. 2C</figref> is a block diagram illustrating a networked environment including a mobile communications device and a server according to an embodiment;
0012<figref idref="DRAWINGS">FIG. 3</figref> is an operational flow diagram illustrating a high level overview of a method for evaluating security during an interactive service operation by a mobile communications device according to an embodiment;
0013<figref idref="DRAWINGS">FIGS. 4A and 4B</figref> illustrate a mobile communications device displaying the security evaluation according to several embodiments; and
0014<figref idref="DRAWINGS">FIGS. 5A-5D</figref> illustrate a mobile communications device displaying a contextual information overlay and a security evaluation according to several embodiments.
DETAILED DESCRIPTION
0015It should be appreciated that the present invention can be implemented in numerous ways, including as a process, an apparatus, a system, a device, a method, or a computer readable medium such as a computer readable storage medium containing computer readable instructions or computer program code, or a computer network wherein computer readable instructions or computer program code are sent over optical or electronic communication links. Applications, software programs or computer readable instructions may be referred to as components or modules. Applications may take the form of software executing on a general purpose computer or be hardwired or hard coded in hardware. Applications may also be downloaded in whole or in part through the use of a software development kit, framework, or toolkit that enables the creation and implementation of the present invention. In this specification, these implementations, or any other form that the invention may take, may be referred to as techniques. In general, the order of the steps of disclosed processes may be altered within the scope of the invention.
0016Systems and methods are provided for evaluating security during an interactive service operation by a mobile communications device that hosts applications including those used for financial transactions and those using sensitive user information. According to an embodiment, “interactive services” may comprise applications running on a mobile communications device that communicate with a website or other server, or a web application running in a web browser on a mobile communications device which communicates with a website to perform an interactive service operation for a user. At least some of the interactive services are configured to communicate with a web server or other server over a network during an interactive service operation. In an embodiment, when an interactive service is launched, the mobile communications device automatically generates a security evaluation for the launched interactive service based on several trust factors that can be related to a current state of the mobile communications device, to a security feature of the interactive service, and/or to a security feature of the network over which information is currently being transmitted or received. Once the evaluation is generated, an action based on the evaluation can be performed. For example, the action can be displaying the security evaluation to a user of the mobile communications device while the user is using the application.
0017In an embodiment, when the security evaluation indicates that the interactive service operation environment is safe and the interactive service is trusted, the user can have some assurance that the user's sensitive information is protected during an interactive service operation. Alternatively, when the security evaluation indicates that there are security concerns with the interactive service operation environment and/or the service, the user can terminate the interactive service operation and/or take measures to improve the security of the interactive service operation.
0018As used herein, the term “mobile communications device” refers to mobile phones, tablets, PDAs and smartphones. The term “mobile communications device” also refers to a class of laptop computers which run an operating system that is also used on mobile phones, tablets, PDAs, or smartphones. Such laptop computers are often designed to operate with a continuous connection to a cellular network or to the internet via a wireless link. Specifically, mobile communications devices include devices for which wireless communication services such as voice, messaging, data, or other wireless Internet capabilities are a primary function. As used herein, a “mobile communications device” may also be referred to as an “electronic device,” an “electronic client device,” “mobile device,” “mobile client,” or “handset.” However, a person having skill in the art will appreciate that while the present invention is disclosed herein as being used on mobile communications devices, the present invention may also be used on other computing platforms, including desktop, laptop, notebook, netbook, or server computers.
0019Prior to describing the subject matter in detail, an exemplary mobile communications device in which the subject matter may be implemented shall first be described. Those of ordinary skill in the art will appreciate that the elements illustrated in <figref idref="DRAWINGS">FIG. 1</figref> may vary depending on the system implementation. With reference to <figref idref="DRAWINGS">FIG. 1</figref>, a block diagram of an embodiment of the mobile communications device <b>101</b> is illustrated. The mobile device <b>101</b> includes: an operating system <b>113</b>, an input device <b>115</b>, a radio frequency transceiver(s) <b>116</b>, a visual display <b>125</b>, and a battery or power supply <b>119</b>. Each of these components is coupled to a central processing unit (CPU) <b>103</b>. The device operating system <b>113</b> runs on the CPU <b>103</b> and enables interaction between application programs and the mobile device hardware components. In an embodiment, the mobile device <b>101</b> receives data through an RF transceiver(s) <b>116</b> which may be able to communicate via various networks, for example: BLUETOOTH, local area networks such as WI-FI, and cellular networks such as GSM, CDMA or LTE.
0020In an embodiment, a local software component <b>175</b> is an application program that is downloaded to a mobile device and installed so that it integrates with the operating system <b>113</b>. Much of the source code for the local software component <b>175</b> can be re-used between various mobile device platforms by using a cross-platform software architecture. In such a system, the majority of software functionality can be implemented in a cross-platform core module. The cross-platform core can be universal allowing it to interface with various mobile device operating systems by using a platform-specific module and a platform abstraction module that both interact with the mobile device operating system <b>113</b>, which is described in U.S. Pat. No. 8,099,472, entitled “SYSTEM AND METHOD FOR A MOBILE CROSS-PLATFORM SOFTWARE SYSTEM.” In another embodiment, the local software component <b>175</b> can be device, platform or operating system specific.
0021The mobile device <b>101</b> may operate in a networked environment using logical connections to one or more remote nodes <b>130</b>, <b>140</b>, <b>150</b> via a communication interface. The remote node may be another computer, a server, a router, a peer device or other common network node, and typically includes many or all of the elements described above relative to the mobile device <b>101</b>. For example, the remote node can be a server <b>130</b> providing a storage service, a web server <b>140</b> that hosts one or more websites <b>142</b> and/or a VPN or proxy server <b>150</b> coupled to a server <b>130</b><i>b </i>and/or a web server <b>140</b>. The communication interface may interface with a wireless network and/or a wired network. Examples of wireless networks include, for example, a BLUETOOTH network, a wireless personal area network, a wireless 802.11 local area network (LAN), a near field communication (NFC), and/or wireless telephony network (e.g., a cellular, PCS, or GSM network). Examples of wired networks include, for example, a LAN, a fiber optic network, a wired personal area network, a telephony network, and/or a wide area network (WAN). Such networking environments are commonplace in intranets, the Internet, offices, enterprise-wide computer networks and the like.
0022It should be understood that the arrangement of mobile communication device <b>101</b> illustrated in <figref idref="DRAWINGS">FIG. 1</figref> is but one possible implementation and that other arrangements are possible. It should also be understood that the various system components (and means) defined by the claims, described below, and illustrated in the various block diagrams represent logical components that are configured to perform the functionality described herein. For example, one or more of these system components (and means) can be realized, in whole or in part, by at least some of the components illustrated in the arrangement of mobile device <b>101</b>. In addition, while at least one of these components are implemented at least partially as an electronic hardware component, and therefore constitutes a machine, the other components may be implemented in software, hardware, or a combination of software and hardware. More particularly, at least one component defined by the claims is implemented at least partially as an electronic hardware component, such as an instruction execution machine (e.g., a processor-based or processor-containing machine) and/or as specialized circuits or circuitry (e.g., discrete logic gates interconnected to perform a specialized function), such as those illustrated in <figref idref="DRAWINGS">FIG. 1</figref>. Other components may be implemented in software, hardware, or a combination of software and hardware. Moreover, some or all of these other components may be combined, some may be omitted altogether, and additional components can be added while still achieving the functionality described herein. Thus, the subject matter described herein can be embodied in many different variations, and all such variations are contemplated to be within the scope of what is claimed.
0023In the description that follows, the subject matter will be described with reference to acts and symbolic representations of operations that are performed by one or more devices, unless indicated otherwise. As such, it will be understood that such acts and operations, which are at times referred to as being computer-executed, include the manipulation by the processing unit of data in a structured form. This manipulation transforms the data or maintains it at locations in the memory system of the device, which reconfigures or otherwise alters the operation of the device in a manner well understood by those skilled in the art. The data structures where data is maintained are physical locations of the memory that have particular properties defined by the format of the data. However, while the subject matter is being described in the foregoing context, it is not meant to be limiting as those of skill in the art will appreciate that various of the acts and operation described hereinafter may also be implemented in hardware.
0024<figref idref="DRAWINGS">FIG. 2A</figref> is a more detailed block diagram of a mobile communications device <b>200</b> having components, and/or their analogs, that are configured to evaluate security during an interactive service operation according to an embodiment. As is shown in <figref idref="DRAWINGS">FIG. 2A</figref>, the mobile communications device <b>200</b> can include an operating system <b>202</b>, a display <b>205</b>, a processor, interactive services <b>206</b>, a network manager component <b>209</b>, a file system <b>203</b> for storing application files and other files, and a plurality of sensors <b>204</b>. In an embodiment, the display <b>205</b> can be configured to present visual content to a user <b>110</b> of the communications device <b>200</b> via a graphical user interface <b>207</b> associated with an application <b>208</b>.
0025The sensors <b>204</b> can include an accelerometer, a biometric reader, a camera, a microphone, a geo-locator, e.g., a Global Positioning System (GPS), and other sensors <b>204</b>. In an embodiment, each sensor <b>204</b> can collect sensor information specific to its sensor type. For example, the biometric reader can collect biometric information of the user <b>110</b> such as fingerprint and/or retina information. According to an embodiment, some sensors <b>204</b> can continuously collect sensor information, which can be provided, upon request, to an application <b>208</b> for further processing. Alternatively, other sensors <b>204</b> can be invoked on an as-needed basis to collect sensor information. For example, the biometric reader can be invoked to collect the finger print information of the user <b>110</b> during an authentication process. It should be understood that the sensors <b>204</b> can include sensors that reside within the mobile communications device <b>200</b> or which reside outside the device but are connected to it by a wired or wireless connection.
0026The interactive services <b>206</b> can include applications <b>208</b> configured to communicate with a server <b>130</b> or with a website <b>142</b> hosted by a web server <b>140</b> over a network <b>120</b>, such as the Internet. For example, an application <b>208</b><i>a </i>associated with an entity, such as a bank, can be configured to transmit data to and receive data from a server <b>130</b><i>a </i>associated with the entity. Alternatively or in addition, interactive services <b>206</b> can include web applications <b>211</b> running in the web browser <b>207</b> and can be configured to communicate with a web server <b>140</b> hosting an associated website <b>142</b>. For example, a web application <b>211</b> associated with the entity that runs in the web browser <b>207</b> can be an interactive service <b>206</b> that is configured to communicate with a target web site <b>142</b><i>a </i>associated with the entity to provide interactive services. In an embodiment, the application <b>208</b> or the web application <b>211</b> running in the browser <b>207</b> can interoperate with the network manager component <b>209</b>, which can be configured to manage network connections between the mobile communications device <b>200</b> and one or more network enabled entities, such as the server <b>130</b>, web servers <b>140</b>, <b>140</b><i>a</i>, and/or proxy servers <b>150</b>.
0027According to an embodiment, the mobile communications device <b>200</b> can be configured to provide an execution environment configured to support operation of an Application Security Assessor (“ASA”) module <b>210</b>. <figref idref="DRAWINGS">FIG. 2B</figref> is a more detailed block diagram representing the ASA module <b>210</b> according to an embodiment. The ASA module <b>210</b> can be configured, in an embodiment, to evaluate security aspects of the device's environment, and of an interactive service <b>206</b>, e.g., an application <b>208</b> or a web application <b>211</b>, while the service is running, and to determine whether it is safe to use the interactive service <b>206</b>, e.g., the application or web application, to perform an interactive service operation. Based on this evaluation, the user can be informed that it is safe to use the interactive service or can be warned that it is not recommended to use the interactive service to perform the interactive service operation.
0028<figref idref="DRAWINGS">FIG. 3</figref> is a flow diagram illustrating a method for evaluating security during an interactive service operation by a mobile communications device according to an embodiment. The method illustrated in <figref idref="DRAWINGS">FIG. 3</figref> can be carried out by, for example, at least some of the components in the example electronic device illustrated in <figref idref="DRAWINGS">FIG. 1</figref>, <figref idref="DRAWINGS">FIG. 2A</figref>, and <figref idref="DRAWINGS">FIG. 2B</figref>, but can also be carried out in environments other than those illustrated in <figref idref="DRAWINGS">FIG. 1</figref>, <figref idref="DRAWINGS">FIG. 2A</figref> and <figref idref="DRAWINGS">FIG. 2B</figref>. According to an embodiment, the method <b>300</b> begins, in block <b>302</b>, when an interactive service configured to communicate with a server is identified or detected as being launched. As stated above, the interactive service <b>206</b> can be an application <b>208</b> that is associated with a particular entity, such as a financial institution, a payment service or an e-commerce service, and the application <b>208</b> can be configured to transmit data to and to receive data from a server <b>130</b><i>a </i>associated with the entity. Alternatively, the launched interactive service <b>206</b> can be a web application <b>211</b> running in the web browser <b>207</b> that is associated with a website <b>142</b> and that allows the user <b>110</b> to access content on the website <b>142</b>.
0029Referring again to <figref idref="DRAWINGS">FIG. 3</figref>, when the interactive service <b>206</b> is launched, a security evaluation is generated based on a plurality of trust factors in block <b>304</b>. In an embodiment, at least one of the trust factors <b>212</b> can be related to a current state of the mobile communications device <b>200</b>, to a security feature of the interactive service <b>206</b>, and/or to a security feature of the network <b>120</b> to and from which data is transmitted and received by the device <b>200</b>. According to an embodiment, when the interactive service <b>206</b> is launched, the ASA module <b>210</b> can be automatically invoked to generate the security evaluation <b>216</b>. In another embodiment, the ASA module <b>210</b> can be invoked by the user <b>110</b>. For example, when an application is <b>208</b> is launched, the user can be asked whether a security check of the launched application <b>208</b> should be performed, and when the user responds affirmatively, the ASA module <b>210</b> can proceed to generate the security evaluation <b>216</b>.
0030Alternatively or in addition, according to an embodiment, an administrator or the user can define for which application(s) or web site(s) the security evaluation <b>216</b> should be generated based on an application type, an application name, or web site URL. For example, in a settings or configuration mode, the applications <b>208</b> can be listed, by type and/or alphabetically, and the user can select for which application(s) the ASA module <b>210</b> should generate security evaluations <b>216</b>. In another embodiment, the administrator or the user can indicate under what circumstances a security evaluation should be generated. For example, the user can configure the ASA module <b>210</b> to determine the security evaluation <b>216</b> for a launched application when the device <b>200</b> is located near a specified geo-location or when the application <b>208</b> is launched during a particular time period.
0031Alternatively or in addition, the administrator or the user can define when the security evaluation <b>216</b> should be generated based on information requested from the user or based on a type of user activity. For example, when a web application <b>211</b> running on the web browser <b>207</b> receives a request for the user's password or credit card number, the ASA module <b>210</b> can be invoked to generate the security evaluation <b>216</b>. In other embodiments, the ASA module <b>210</b> can be configured to generate a security evaluation <b>216</b> based on other factors and/or a combination of circumstances and factors.
0032As noted above, the security evaluation <b>216</b> is generated based on a plurality of trust factors <b>212</b>. In an embodiment, the trust factors <b>212</b> are related to factors affecting the security environment within and around the mobile communications device <b>200</b> and can be used to evaluate how safe it is to perform an interactive service operation using the launched interactive service <b>206</b> on the device <b>200</b>. According to an embodiment, the plurality of trust factors <b>212</b> can be associated with a plurality of security subscores <b>214</b> so that each trust factor <b>212</b> can be evaluated and scored. It should be understood that alternative means of quantifying a security evaluation besides numeric scores, including letter grading (“A,” “B”, “C”, “D”, “F”) or outputting a category or classification (e.g., “safe” or “unsafe” or “suspicious”) can be used.
0033For instance, in an embodiment, a trust factor <b>212</b> can be related to the state of the mobile communications device <b>200</b> at the time the security evaluation <b>216</b> is generated, e.g., when the application <b>208</b> is launched or when sensitive user information is requested from a website <b>142</b>. In an embodiment, for example, a trust factor <b>212</b><i>a </i>can be directed to whether the device <b>200</b> is protected by an anti-malware software application. Here, the ASA module <b>210</b> can determine the security subscore <b>214</b><i>a </i>associated with the trust factor <b>212</b><i>a</i>, in an embodiment, by searching the file system <b>203</b> for a known anti-malware application. When such an application is not found, the trust factor <b>212</b><i>a </i>is not satisfied and a security risk exists. In this case, the ASA module <b>210</b> can be configured to set the security subscore <b>214</b><i>a </i>to a value greater than zero, which signifies that a security risk exists. Otherwise, when the device <b>200</b> is protected by an anti-malware application, the security subscore can be set to zero.
0034Alternatively or in addition, another trust factor <b>212</b><i>a </i>related to the state of the mobile communications device <b>200</b> can be directed to whether suspicious programming code, i.e., malware, is detected on the device <b>200</b>. In this case, the ASA module <b>210</b> can determine the security score, in an embodiment, by scanning the applications <b>208</b> on the device <b>200</b> to detect malware. The ASA module <b>210</b>, for instance, can invoke an anti-malware software application, when one exists, to scan application files stored in the file system <b>203</b> and to identify malicious programming code and/or suspicious activity. When malware is detected, a security risk exists and the ASA module <b>210</b> can be configured to set the security subscore <b>214</b><i>a </i>to a value greater than zero. Otherwise, when the device <b>200</b> is malware-free, the security subscore <b>214</b><i>a </i>can be set to zero.
0035In another embodiment, yet another trust factor <b>212</b><i>a </i>related to the state of the mobile communications device <b>200</b> can be directed to whether the mobile communications device <b>200</b> is lost or stolen. Here, the security subscore <b>214</b><i>a </i>can be determined, in an embodiment, by transmitting a query to a service provider associated with the mobile communications device <b>200</b> to determine whether the device <b>200</b> has been reported as being lost or stolen. When the device <b>200</b> is lost or stolen, the ASA module <b>210</b> can be configured to set the security subscore <b>214</b><i>a </i>to a value greater than zero, and when the device <b>200</b> is not, the security subscore <b>214</b><i>a </i>can be set to zero. Other trust factors <b>212</b><i>a </i>related to the state of the mobile communications device <b>200</b> can be directed to identifying other open applications <b>208</b><i>a</i>, <b>208</b><i>b </i>and determining whether they pose a security threat; identifying the version, patch and/or patch-level of the operating system <b>202</b>; and identifying other web applications <b>211</b> the web browser <b>207</b> may be accessing and determining whether those web applications <b>211</b> post a security threat.
0036In addition, a trust factor <b>212</b> can be related to a security feature of the launched interactive service <b>206</b>. For instance, in an embodiment, such a trust factor <b>212</b><i>b </i>can be directed to whether an application <b>208</b> was downloaded from a trusted source and/or whether the launched application <b>208</b> is authentic or trusted. In this embodiment, the ASA module <b>210</b> can be configured to determine that the application <b>208</b> is trusted by verifying that its hash matches the hash of the known authentic application or that the signer of the application matches the signer of the known authentic application, and by ensuring that the source from which it was downloaded is on a whitelist of trusted sources and/or not on a blacklist of suspicious sources. In addition, a trust factor <b>212</b><i>b </i>can be directed to whether the application <b>208</b> is up-to-date, and the ASA module <b>210</b> can be configured to determine that the application <b>208</b> is up-to-date by querying the trusted source of the application <b>208</b> or by retrieving information about the latest version of the application from a server <b>130</b> that can obtain the information in real-time from the trusted source of the application <b>208</b> or that can store the information in cache from a prior request to provide such information.
0037In another embodiment, a trust factor <b>212</b><i>b </i>related to a security feature of the launched application <b>208</b> can be directed to whether the interactive service <b>206</b> encrypts data transmitted to a web site <b>142</b>, e.g., using HTTPS. In addition, when the interactive service is a web application <b>211</b>, a trust factor <b>212</b><i>b </i>can be directed to whether the application <b>211</b> is miming in a web browser <b>207</b> that is able to understand and support security policies defined by content providers. For example, Content Security Policy (CSP) (http://www.w3.org/TR/CSP/) can be used by content providers to inform a web browser from where content expects to be loaded, so that a web browser that supports CSP will only execute scripts loaded in source files received from those whitelisted domains, ignoring all other script. In addition, a trust factor <b>212</b><i>b </i>related to a security feature of the launched interactive service <b>206</b> can be directed to whether the service <b>206</b> stores sensitive and confidential user data on the mobile communications device <b>200</b> and if so, whether that data is accessible by other applications <b>208</b><i>a</i>, <b>208</b><i>b </i>running on the device <b>200</b>. According to an embodiment, when at least one of these trust factors <b>212</b><i>b </i>is not satisfied, the respective security subscore(s) <b>214</b><i>b </i>can be set to a value greater zero. Alternatively or in addition, another trust factor <b>212</b><i>b </i>related to a security feature of the launched application <b>208</b> can be directed to whether there exists in the web application <b>211</b> an attempted exploit of a vulnerability of the browser or the mobile communications device. In such a case the ASA module <b>210</b> can notify the developer of the application <b>208</b> or the entity associated with the interactive service <b>206</b>.
0038In an additional embodiment, a trust factor <b>212</b> can be related to a security feature of the network <b>120</b> over which the launched interactive service <b>206</b> sends and receives data. For instance, in an embodiment, such a trust factor <b>212</b><i>c </i>can be directed to whether the network <b>120</b> is a secure network. Here, the ASA module <b>210</b> can be configured to query the network manager component <b>209</b> to determine whether the network <b>120</b> to which the device <b>200</b> is connected is an open network or a private network requiring proper credentials. According to an embodiment, when such a trust factor <b>212</b><i>c </i>is not satisfied, a security risk exists, and therefore, the ASA module <b>210</b> can set the security subscore <b>214</b><i>c </i>to a value greater than zero.
0039According to an embodiment, when first <b>212</b><i>a </i>and second <b>212</b><i>b </i>trust factors are not satisfied, the security subscore <b>214</b><i>a </i>of the first trust factor <b>212</b><i>a </i>and the security subscore <b>214</b><i>b </i>of the second trust factor <b>212</b><i>b </i>can be set to different values greater than zero to reflect the difference in security risks posed by the different trust factors <b>212</b><i>a</i>, <b>212</b><i>b</i>. For example, when the first trust factor <b>212</b><i>a </i>is directed to whether the interactive service encrypts outgoing data and the second trust factor <b>212</b><i>b </i>is directed to whether the network <b>120</b> is secure, it may be deemed that sending unencrypted data may pose a greater security risk than being connected to an unsecured network. In that case, the value of the security subscore <b>214</b><i>a </i>of the first trust factor <b>212</b><i>a </i>can be greater than the second trust factor's security subscore value <b>214</b><i>b </i>to reflect this difference in security exposure. According to an embodiment, the subscore values <b>214</b> for the plurality of trust factors <b>212</b> can be defined by an administrator, a user, and/or by default.
0040Once the plurality of trust factors <b>212</b> have been evaluated and scored, the ASA module <b>210</b> can determine a security score <b>215</b>, in an embodiment, by accumulating the security subscores <b>214</b> associated with the plurality of trust factors <b>212</b>. According to an embodiment, the security evaluation <b>216</b> can be generated based on the security score <b>215</b>. For example, when the security score <b>215</b> is greater than a threshold value <b>218</b>, the ASA module <b>210</b> can be configured to generate a security evaluation <b>216</b> that indicates that it is not recommended to perform the interactive service operation. Conversely, when the security score <b>215</b> is at most equal to the threshold value <b>218</b>, the generated security evaluation <b>216</b> can indicate that it is safe to perform the interactive service operation.
0041According to an embodiment, the threshold value <b>218</b> can be zero so that when any one of the trust factors <b>212</b> is not satisfied, the security evaluation <b>216</b> indicates that it is not recommended to proceed with the interactive service operation. In another embodiment, the threshold value <b>218</b> can be greater than zero so that it is possible for the security evaluation <b>216</b> to indicate that it is safe to proceed with the interactive service operation even though a trust factor <b>212</b> is not satisfied. In an embodiment, more than one threshold value <b>218</b>, <b>218</b><i>a </i>greater than zero can be defined. In this embodiment, more than two security evaluations <b>216</b> can be generated thereby providing more nuanced guidance. For example, when the security score <b>215</b> is greater than a first threshold value <b>218</b> but less than a second threshold value <b>218</b><i>a</i>, the ASA module <b>210</b> can be configured to generate a security evaluation <b>216</b> that indicates that it is not absolutely safe to perform the interactive service operation, and to proceed with caution.
0042Referring again to <figref idref="DRAWINGS">FIG. 3</figref>, once the security evaluation <b>216</b> is generated, an action based on the security evaluation <b>216</b> is performed in block <b>306</b>. For example, in an embodiment, the action performed can include terminating the interactive service operation when the security evaluation <b>216</b> indicates that it is not safe to perform the interactive service operation. Here, the ASA module <b>210</b> can direct the network manager component <b>209</b> to block data traffic from and to the interactive service <b>206</b> and/or can disable the interactive service <b>206</b>. Alternatively, or in addition, in an embodiment, the action performed can include displaying the security evaluation <b>216</b> to the user of the mobile communications device <b>200</b> while the user is using the interactive service <b>206</b>.
0043<figref idref="DRAWINGS">FIG. 4A</figref> illustrates a mobile communications device displaying the security evaluation according to an embodiment. As is shown, the device <b>400</b> includes a display screen <b>402</b> that includes a notification bar <b>404</b> and a window for displaying a GUI associated with a launched application <b>208</b>. In an embodiment, the security evaluation <b>216</b> can be a notification icon <b>406</b>, such as a padlock, that is displayed in the notification bar <b>404</b>. Unlike the typical web browser that displays a padlock icon to represent only the fact that the web browser has a secure connection to a website using the HTTPS protocol (over SSL or TLS); the notification icon <b>406</b> described herein represents the overall security assessment which includes a variety of additional trust factors. Additionally, the notification icon <b>406</b> is displayed in the mobile communication device's notification bar and not within the user interface <b>201</b> provided by the web browser.
0044In an embodiment, different security evaluations <b>216</b> can be represented by different types of notification icons or by differently colored notification icons <b>406</b>. For instance, the notification icon <b>406</b> can be a red lock when the security evaluation <b>216</b> indicates that it is not recommended to proceed with the interactive service operation, a yellow lock when it is not absolutely safe to perform the interactive service operation, and to proceed with caution, or a green lock when it is safe to proceed with the interactive service operation.
0045In another embodiment, shown in <figref idref="DRAWINGS">FIG. 4B</figref>, the security evaluation <b>216</b> can be displayed in a banner <b>410</b> that is superimposed over the GUI associated with the interactive service <b>206</b>. In this embodiment, the banner <b>410</b> can include the notification icon <b>406</b> to provide a quick visual check and text <b>412</b> indicating that the application is safe.
0046According to an embodiment, additional contextual information relating to the security evaluation <b>216</b> can be displayed, for example, by selecting, e.g., touching, the banner <b>410</b>. In an embodiment, the contextual information can be displayed in a contextual information overlay, which can be superimposed over the GUI associated with the interactive service <b>206</b> or presented in a separate window. <figref idref="DRAWINGS">FIGS. 5A-5D</figref> illustrate a mobile communications device displaying a contextual information overlay and a security evaluation according to an embodiment. As is shown in <figref idref="DRAWINGS">FIG. 5A</figref>, the contextual information overlay <b>500</b> is associated with the security evaluation <b>216</b>, e.g., the notification icon <b>406</b>, and provides contextual information relating to the security evaluation <b>216</b>. In an embodiment, the overlay <b>500</b> can provide a summary <b>504</b> describing the security evaluation <b>216</b> and can include a checklist <b>502</b> that provides contextual information supporting the summary <b>504</b>. For example, the checklist <b>502</b> can include information regarding a current security status of the mobile communications device <b>501</b>, a security status of the launched interactive service <b>206</b>, and/or to a security status of the network <b>120</b>. Accordingly, in <figref idref="DRAWINGS">FIG. 5A</figref>, the summary <b>504</b> indicates “Everything is OK,” and the checklist <b>502</b> confirms that indication. In contrast, in <figref idref="DRAWINGS">FIG. 5B</figref>, the summary <b>504</b><i>a </i>indicates “There is a problem,” and the checklist <b>502</b><i>a </i>confirms this indication because the device <b>501</b><i>a </i>is connected via an unsecured network.
0047In <figref idref="DRAWINGS">FIG. 5A</figref> and <figref idref="DRAWINGS">FIG. 5B</figref>, the contextual information overlay <b>500</b>, <b>500</b><i>a </i>provides contextual information relating specifically to security concerns. In another embodiment, contextual information relating specifically to privacy and connection concerns can also be displayed. The contextual information overlay <b>500</b> can include, in an embodiment, information navigation tabs <b>506</b> that provide access to privacy and connection information when selected. For example, when the privacy tab <b>506</b><i>a </i>is selected, privacy information <b>520</b> associated with the interactive service <b>206</b> is displayed, as shown in <figref idref="DRAWINGS">FIG. 5C</figref>, and when the connection tab <b>506</b><i>b </i>is selected, connection information <b>530</b> is displayed, as shown in <figref idref="DRAWINGS">FIG. 5D</figref>.
0048According to an embodiment, the ASA module <b>210</b> can be configured to perform additional security functions to enhance security and to ensure that the interactive service operation is performed in a safe environment. For instance, as indicated above, the launched interactive service <b>206</b> can be an application <b>208</b><i>a </i>or a web application <b>211</b> that is purportedly associated with a specific entity, such as a financial institution, and that is configured to transmit data to and to receive data from a target website <b>142</b><i>a</i>. In this case, in addition to generating the security evaluation <b>216</b> for the interactive service <b>206</b>, the ASA module <b>210</b> can verify that the interactive service <b>206</b> is sending data to a website that is an authentic target website <b>142</b><i>a </i>associated with the specified entity and not a fraudulent website posing as the target website <b>142</b><i>a</i>. For example, in an embodiment, the ASA module <b>210</b> can examine a uniform resource location (URL) of the target website <b>142</b><i>a </i>to identify a domain. Once the domain is identified, the ASA module <b>210</b> can determine whether the domain is registered by the specified entity by querying a domain registrar. The interactive service can purport to be associated with a specific entity by using text or images associated with or identifying the name of the entity or its logo or trademarks, or by using the name of the entity or its trademarks within the URL domain or path, or text designed to be confusingly similar to the name of the entity or its trademarks. In such a case the ASA module <b>210</b> can notify the developer of the application <b>208</b> or the entity associated with the interactive service <b>206</b>. In an embodiment, the ASA module <b>210</b> can redirect the web browser <b>207</b> to the legitimate website or web application <b>211</b> that is actually associated with the entity.
0049In addition, the ASA module <b>210</b> can check the characters of the URL to detect visually ambiguous substitutions, e.g., one (1) and the lowercase letter “L.” Moreover, the ASA module <b>210</b> can examine the placement of certain phrases referring to the entity within the URL to detect a fraudulent website. For example, “online.com/Citibank” can be a URL for a website posing as an authentic website having a URL “Citibank.online.com.” When the purported target website is a fraudulent website, the ASA module <b>210</b> can generate and display to the user a security warning indicating that the interactive service <b>206</b> is suspicious. In addition, the ASA module <b>210</b> can be configured to block the interactive service operation and to quarantine the interactive service <b>206</b> for further security analysis. In addition, the ASA module <b>210</b> can display one type of visual indicator or badge atop the display of the interactive service to indicate the level of trust or safety as determined by the ASA module. In such a case, the ASA module <b>210</b> can notify the developer of the application <b>208</b> or the entity associated with the interactive service <b>206</b>.
0050In another embodiment, the ASA module <b>210</b> can be configured to take additional security measures when certain trust factors <b>212</b> are not satisfied. For instance, when the trust factor <b>212</b><i>a </i>is directed to whether the mobile communications device <b>200</b> is lost or stolen, and the security subscore <b>214</b><i>a </i>is set to a value greater than zero because the device is reported lost or stolen, the ASA module <b>210</b> can be configured to lock the mobile communication device <b>200</b> so that it is inoperable. In addition, when the launched interactive service <b>206</b> is one that accesses a target website <b>142</b><i>a</i>, the ASA module <b>210</b> can transmit a notification message to the target website <b>142</b><i>a </i>warning it that the device <b>200</b> is lost or stolen. In another embodiment, when the trust factor <b>212</b><i>c </i>directed to whether the network is a secure network is not satisfied, the ASA module <b>210</b> can be configured to invoke the network manager component <b>209</b> to detect another network <b>120</b><i>a </i>that is a secure network. When the secure network <b>120</b><i>a </i>is detected, the ASA module <b>210</b> can instruct the network manager component <b>209</b> to disconnect the device <b>200</b> from the unsecured network <b>120</b>, and to connect to the secure network <b>120</b><i>a</i>. When the connection to the secure network <b>120</b><i>a </i>is established, the security subscore <b>214</b><i>c </i>associated with the trust factor <b>212</b><i>c </i>can be reset to zero.
0051According to an embodiment, in addition to generating the security evaluation <b>216</b> for the interactive service <b>206</b>, the ASA module <b>210</b> can also authenticate the user of the mobile communications device <b>200</b> to ensure that the user is authorized to perform the interactive service operation. The user can be authenticated based on information known to the device's registered user in an embodiment. For example, the user can be asked to submit a password, to identify recently visited websites using the device <b>200</b>, to confirm applications <b>208</b> installed on the device <b>200</b>, and/or to identify favorite contacts stored on the device <b>200</b>.
0052In another embodiment, the user can be authenticated based on a geo-location of the mobile communications device <b>200</b> and/or sensor data collected by the device <b>200</b>. For example, the ASA Module <b>210</b> can be configured to identify the device's geo-location using the device's GPS sensor <b>204</b> and to compare the device's location to a known location of the user. When the device's location is near the user's known location, the user can be authenticated. In another embodiment, the ASA module <b>210</b> can collect the user's biometric information via the biometric reader sensor <b>204</b> and compare the collected information to stored biometric information to authenticate the user.
0053In another embodiment, the ASA module <b>210</b> can authenticate the user of the device <b>200</b> by determining that another mobile communications device known to be associated with the user is nearby. In this case, the ASA module <b>210</b> can transmit a request to the other mobile communications device via a short-range network, such as a BLUETOOTH or NFC network. When the ASA module <b>210</b> receives a response from the other mobile communications device, the user can be authenticated.
0054In addition to generating the security evaluation <b>216</b> and to implementing the additional security measures described above, the ASA module <b>210</b> can enhance the security during an interactive service operation by blocking access to certain internal resources by all applications <b>208</b> or web applications <b>211</b> during the interactive service operation and/or blocking communications with certain network locations. For example, during a interactive service operation, third party browser plugins and other components capable of intercepting the interactive service operation can be disabled, and access to network logs, process files, and web history can be blocked. Moreover, the ASA module <b>210</b> can close or suspend certain applications or all other applications during the interactive service operation.
0055In the embodiments described and illustrated in <figref idref="DRAWINGS">FIG. 2A</figref>, the ASA module <b>210</b> is implemented on the mobile communications device <b>200</b>. In another embodiment, the ASA module can also be implemented on a server, as shown in <figref idref="DRAWINGS">FIG. 2C</figref>. In this embodiment, the server <b>230</b> can be configured to host an ASA module <b>220</b> that is configured to perform at least some, if not all, of the tasks performed by the local ASA module <b>210</b> on the mobile communications device <b>200</b><i>a. </i>
0056For example, in an embodiment, the server's ASA module <b>220</b> can be configured to receive an indication from the mobile communications device <b>200</b><i>a </i>that an interactive service <b>206</b> has been launched, and in response, the ASA module <b>220</b> can be configured to generate a security evaluation <b>226</b> based on trust factors <b>222</b>. In an embodiment, the trust factors <b>222</b> can be related to conditions described above. Alternatively, or in addition, the trust factors <b>222</b> can be related to other security concerns, such as a reputation of the interactive service <b>206</b>. In this case, the reputation can be determined from social media and/or social networking web sites. In an embodiment, the action performed by the mobile communication device <b>200</b><i>a </i>can be based on either or both of the device's security evaluation <b>216</b> and the server's security evaluation <b>226</b>.
0057In another embodiment, the server's ASA module <b>220</b> can receive the security subscores <b>214</b> of the device's trust factors <b>212</b> from the device <b>200</b><i>a</i>, determine a security score <b>225</b>, and then return the security score <b>225</b> to the device <b>200</b><i>a</i>, which then generates the security evaluation <b>216</b>. Alternatively, in another embodiment, the server's ASA module <b>220</b> can receive the security subscores <b>214</b>, determine the security score <b>225</b>, generate the security evaluation <b>226</b> based on the security score <b>225</b> and then return the evaluation <b>226</b> to the device <b>200</b><i>a</i>, which then performs the appropriate action. In yet another embodiment, the server's ASA module <b>220</b> can generate the security evaluation <b>226</b> based on the security score <b>225</b>, determine the action that should be performed based on the evaluation <b>226</b>, and perform the action and/or direct the device <b>200</b><i>a </i>to perform the action.
0058According to an embodiment, the server <b>230</b> can be a dedicated server that hosts a service configured to provide security services to a plurality of mobile communications devices <b>200</b>. Alternatively, the server <b>230</b> can be an intermediary server that receives and transmits data between the device <b>200</b> and other servers <b>130</b> and/or web servers <b>140</b>. In this case, the server <b>230</b> can be a VPN server <b>150</b>, which tunnels communications between the device <b>101</b> and a server <b>130</b><i>b</i>, or it can be a configured proxy web server <b>150</b>.
0059Any of the above embodiments may be used alone or together with one another in any combination. The one or more implementations encompassed within this specification may also include embodiments that are only partially mentioned or alluded to or are not mentioned or alluded to at all. Although various embodiments may have been motivated by various deficiencies with the prior art, which may be discussed or alluded to in one or more places in the specification, the embodiments do not necessarily address any of these deficiencies. In other words, different embodiments may address different deficiencies that may be discussed in the specification. Some embodiments may only partially address some deficiencies or just one deficiency that may be discussed in the specification, and some embodiments may not address any of these deficiencies.
0060In addition, one will appreciate that in the description above and throughout, numerous specific details are set forth in order to provide a thorough understanding of the present invention. It will be evident, however, to one of ordinary skill in the art, that the present invention may be practiced without these specific details. In other instances, well-known structures and devices are shown in block diagram form to facilitate explanation.
0061While one or more implementations have been described by way of example and in terms of the specific embodiments, it is to be understood that one or more implementations are not limited to the disclosed embodiments. To the contrary, it is intended to cover various modifications and similar arrangements as would be apparent to those skilled in the art. Therefore, the scope of the appended claims should be accorded the broadest interpretation so as to encompass all such modifications and similar arrangements.
Contents6
10 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| USD1090564S | Cited by | United States of America | Search report |
| USD1098181S | Cited by | United States of America | Search report |
| US11636416B2 | Cited by | United States of America | Applicant |
| US2004209608A1 | Cites | United States of America | Applicant |
| US2005138450A1 | Cites | United States of America | Applicant |
| US2005186954A1 | Cites | United States of America | Applicant |
| US2005221800A1 | Cites | United States of America | Applicant |
| US2006085357A1 | Cites | United States of America | Applicant |
| US2006212931A1 | Cites | United States of America | Search report |
| US2006217115A1 | Cites | United States of America | Applicant |
| US2006236325A1 | Cites | United States of America | Applicant |
| US2007021112A1 | Cites | United States of America | Applicant |
| US2007038677A1 | Cites | United States of America | Applicant |
| US2007089165A1 | Cites | United States of America | Applicant |
| US2007090954A1 | Cites | United States of America | Applicant |
| US2007190995A1 | Cites | United States of America | Applicant |
| US2007240127A1 | Cites | United States of America | Applicant |
| US2008046369A1 | Cites | United States of America | Applicant |
| US2008047007A1 | Cites | United States of America | Search report |
| US2008049653A1 | Cites | United States of America | Applicant |
| US2008086638A1 | Cites | United States of America | Applicant |
| US2008244407A1 | Cites | United States of America | Applicant |
| US2008307243A1 | Cites | United States of America | Applicant |
| US2009006956A1 | Cites | United States of America | Applicant |
| US2009064330A1 | Cites | United States of America | Applicant |
| US2009119143A1 | Cites | United States of America | Applicant |
| US2009172227A1 | Cites | United States of America | Applicant |
| US2009205016A1 | Cites | United States of America | Applicant |
| US2009300511A1 | Cites | United States of America | Applicant |
| US2010019731A1 | Cites | United States of America | Applicant |
| US2010097494A1 | Cites | United States of America | Applicant |
| US2010100591A1 | Cites | United States of America | Applicant |
| US2010100939A1 | Cites | United States of America | Applicant |
| US2010100959A1 | Cites | United States of America | Applicant |
| US2010100963A1 | Cites | United States of America | Applicant |
| US2010100964A1 | Cites | United States of America | Applicant |
| US2010210240A1 | Cites | United States of America | Applicant |
| US2010240419A1 | Cites | United States of America | Applicant |
| US2010262924A1 | Cites | United States of America | Applicant |
| US2010275127A1 | Cites | United States of America | Applicant |
| US2011047033A1 | Cites | United States of America | Applicant |
| US2011047594A1 | Cites | United States of America | Applicant |
| US2011047597A1 | Cites | United States of America | Applicant |
| US2011047620A1 | Cites | United States of America | Applicant |
| US2011119765A1 | Cites | United States of America | Applicant |
| US2011145920A1 | Cites | United States of America | Applicant |
| US2011171923A1 | Cites | United States of America | Applicant |
| US2011225492A1 | Cites | United States of America | Applicant |
| US2011225505A1 | Cites | United States of America | Applicant |
| US2011241872A1 | Cites | United States of America | Applicant |
| US2011289423A1 | Cites | United States of America | Applicant |
| US2011296510A1 | Cites | United States of America | Applicant |
| US2012042382A1 | Cites | United States of America | Applicant |
| US2012060222A1 | Cites | United States of America | Applicant |
| US2012072569A1 | Cites | United States of America | Applicant |
| US2012084836A1 | Cites | United States of America | Applicant |
| US2012084864A1 | Cites | United States of America | Applicant |
| US2012096555A1 | Cites | United States of America | Applicant |
| US2012110174A1 | Cites | United States of America | Applicant |
| US2012124239A1 | Cites | United States of America | Applicant |
| US2012179801A1 | Cites | United States of America | Applicant |
| US2012179814A1 | Cites | United States of America | Applicant |
| US2012185780A1 | Cites | United States of America | Applicant |
| US2012188064A1 | Cites | United States of America | Applicant |
| US2012196571A1 | Cites | United States of America | Applicant |
| US2012233695A1 | Cites | United States of America | Applicant |
| US2012259954A1 | Cites | United States of America | Applicant |
| US2012303735A1 | Cites | United States of America | Applicant |
| US2012317233A1 | Cites | United States of America | Applicant |
| US2012324076A1 | Cites | United States of America | Applicant |
| US2012324094A1 | Cites | United States of America | Applicant |
| US2012324568A1 | Cites | United States of America | Applicant |
| US2013019311A1 | Cites | United States of America | Applicant |
| US2014331275A1 | Cites | United States of America | Search report |
| US5715518A | Cites | United States of America | Applicant |
| US6696941B2 | Cites | United States of America | Applicant |
| US6892225B1 | Cites | United States of America | Applicant |
| US7159237B2 | Cites | United States of America | Applicant |
| US7181252B2 | Cites | United States of America | Applicant |
| US7304570B2 | Cites | United States of America | Applicant |
| US7346605B1 | Cites | United States of America | Applicant |
| US7493403B2 | Cites | United States of America | Applicant |
| US7761583B2 | Cites | United States of America | Applicant |
| US7783281B1 | Cites | United States of America | Applicant |
| US7809366B2 | Cites | United States of America | Applicant |
| US7877784B2 | Cites | United States of America | Applicant |
| US7991854B2 | Cites | United States of America | Applicant |
| US8087082B2 | Cites | United States of America | Applicant |
| US8108555B2 | Cites | United States of America | Applicant |
| US8121617B1 | Cites | United States of America | Applicant |
| US8135395B2 | Cites | United States of America | Applicant |
| US8195196B2 | Cites | United States of America | Applicant |
| US8259568B2 | Cites | United States of America | Applicant |
| US8261351B1 | Cites | United States of America | Applicant |
| US8266288B2 | Cites | United States of America | Applicant |
| US8266324B2 | Cites | United States of America | Applicant |
| US8346860B2 | Cites | United States of America | Applicant |
| US8356080B2 | Cites | United States of America | Applicant |
| US8364785B2 | Cites | United States of America | Applicant |
| US8521131B1 | Cites | United States of America | Applicant |
6 members in 1 office; this record represents the family
Members6
| Document | Office | Kind | |
|---|---|---|---|
| US2014325586A1 | United States of America | A1 | |
| USD727943S | United States of America | S | |
| USD728602S | United States of America | S | |
| USD728603S | United States of America | S | |
| USD728604S | United States of America | S | |
| US9307412B2This record | United States of America | B2 |
51 transactions on the USPTO file
Allowed after 1 non-final rejection.
- Non-final rejections
- 1
- Final rejections
- 0
- RCEs
- 0
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Applicant Has Filed a Verified Statement of Small Entity Status in Compliance with 37 CFR 1.27SMAL | SMAL | |
| Payment of Maintenance Fee, 8th Year, Large EntityM1552 | M1552 | |
| Entity Status Set To Undiscounted (Initial Default Setting or Status Change)BIG. | BIG. | |
| Payment of Maintenance Fee, 4th Yr, Small EntityM2551 | M2551 | |
| Correspondence Address ChangeC.ADB | C.ADB | |
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Miscellaneous Incoming LetterLET. | LET. | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Reasons for AllowanceEX.R | EX.R | |
| Examiner's Amendment CommunicationEX.A | EX.A | |
| Interview Summary - Examiner Initiated - TelephonicEXET | EXET | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Application ready for PDX access by participating foreign officesCCRDY | CCRDY | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| PG-Pub Issue NotificationPG-ISSUE | PG-ISSUE | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Preliminary AmendmentA.PE | A.PE | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| FITF set to YES - revise initial settingFTFS | FTFS | |
| FITF set to NO - revise initial settingFTFI | FTFI | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Application Is Now CompleteCOMP | COMP | |
| Sent to Classification ContractorPGPC | PGPC | |
| Filing ReceiptFLRCPT.O | FLRCPT.O | |
| Applicant Has Filed a Verified Statement of Small Entity Status in Compliance with 37 CFR 1.27SMAL | SMAL | |
| Cleared by OIPE CSRL194 | L194 | |
| Reference capture on IDSRCAP | RCAP | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Applicants have given acceptable permission for participating foreignAPPERMS | APPERMS | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Entity status set to undiscounted (initial default setting or status change)BIG. | BIG. | |
| Initial Exam Team nnIEXX | IEXX |
17 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| Fee payment procedureENTITY STATUS SET TO SMALL (ORIGINAL EVENT CODE: SMAL); ENTITY STATUS OF PATENT OWNER: SMALL ENTITYFEPP | FEPP | |
| Maintenance fee paymentMAFP | MAFP | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| Fee payment procedureENTITY STATUS SET TO UNDISCOUNTED (ORIGINAL EVENT CODE: BIG.); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| AssignmentAS | AS | |
| Maintenance fee paymentMAFP | MAFP | |
| AssignmentAS | AS | |
| Certificate of correctionCC | CC | |
| AssignmentAS | AS | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| AssignmentAS | AS |
Numbers
- Publication
- 9307412
- Application
- 14072718
Titles
- English
- Method and system for evaluating security for an interactive service operation by a mobile device
Patent term adjustment
- A delay
- +224 daysthe office missed an examination deadline
- Applicant delay
- −117 days
- Net adjustment
- 107 days
Classification
- CPC, 8
- H04W12/12
- H04L63/126
- H04L63/1433
- H04L63/1483
- H04W12/67
- H04W12/63
- H04W12/128
- H04W12/30
- IPC, 3
- G06F17 00
- H04L29 06
- H04W12 12
- USPC, 1
- 001001000